Summary
- Nvidia Open Agent Safety Platform combines the OpenShell runtime boundary with a Sentry reference design using BlueField-4 hardware.
- OpenShell can trace and restrict agent actions outside the model itself and can be extended beyond Nvidia CPUs to Arm and Intel systems.
- More than 100 organisations are working with the technologies, including SAP, Salesforce, Microsoft, and major infrastructure and financial-services companies.
Nvidia has launched an open security platform intended to constrain autonomous AI agents at the software and hardware layers beneath them, moving part of the control problem away from the model itself as companies give AI systems greater access to applications, data, and infrastructure.
The Open Agent Safety Platform combines OpenShell, an open-source secure runtime that traces actions and enforces policies while an agent operates, with a reference system design called Sentry that uses Nvidia BlueField-4 data-processing units to monitor agent behaviour independently of the software running above it.
Nvidia says Sentry can quarantine an agent in milliseconds when it attempts to move beyond defined boundaries, while OpenShell establishes restrictions around the tools, data, and services an agent can reach. Although OpenShell is optimised for Nvidia’s Vera CPUs, the company says the open-source software can be extended to third-party computing platforms including Arm and Intel.
The architecture reflects a problem that becomes harder as agents move beyond generating text and begin taking actions. A conventional chatbot can provide an incorrect answer without necessarily altering a business system, whereas an agent connected to code repositories, cloud infrastructure, customer records, or industrial equipment can turn a mistaken or malicious instruction into an operational event.
Security controls move outside the agent
Many existing safeguards operate inside the model or the application hosting it. Developers can instruct an agent not to access particular information, require an approval step in the user interface, or design prompts intended to constrain its behaviour, but those controls depend partly on software the agent is already interacting with.
Nvidia’s design assumes that important boundaries should also exist outside that environment. OpenShell creates a runtime layer between the agent and the resources it wants to use, while Sentry is designed to monitor activity from a separate hardware trust domain that the agent itself does not control.
The approach resembles established computer-security practice. Sandboxing limits what software can reach, least-privilege access restricts permissions, network controls separate systems, and independent monitoring looks for behaviour that violates policy. Agentic AI changes the context rather than eliminating those principles.
That distinction has become more useful as AI failures show how application-level assumptions can break. OpenAI’s own post-mortem of an evaluation escaping into production systems illustrated how autonomous software can encounter infrastructure paths that designers did not expect, even when the original experiment is tightly scoped.
An enterprise agent creates similar problems at a larger scale because its usefulness often depends on broad context. A system asked to troubleshoot an application may need access to logs, cloud consoles, code, tickets, and deployment tools; restricting that access too heavily reduces its value, while granting excessive authority increases the consequences of compromise or error.
The platform is also an ecosystem play
Nvidia says more than 100 organisations are working with technologies around the platform, spanning enterprise software, security, financial services, industrial infrastructure, robotics, and cloud computing. Named participants include Anthropic, Cisco, CrowdStrike, Dell, Hugging Face, Microsoft, Palantir, Salesforce, SAP, ServiceNow, and others.
SAP is integrating OpenShell with its Joule Studio runtime, while Salesforce and Nvidia have integrated it with Slack so teams can review agent activity and approve or reject requests for additional permissions. Those examples move the platform beyond an Nvidia-only security layer and into business applications where companies are already experimenting with agents.
Financial-services and industrial organisations are also participating, giving the programme relevance beyond general office automation. Autonomous systems operating around regulated data, energy infrastructure, industrial processes, or software deployment encounter stricter boundaries than assistants confined to document generation.
The commercial interest for Nvidia is equally clear. The company already supplies much of the computing hardware used to train and run advanced AI, and agent security gives it another architectural layer around those workloads. Sentry in particular ties monitoring to BlueField hardware, while OpenShell gives Nvidia a route into deployments running on CPUs from other suppliers.
That combination creates a tension familiar from open infrastructure projects. Open-source components can encourage broad adoption and interoperability, while hardware integration gives Nvidia an opportunity to make its own systems the most tightly integrated implementation. Enterprise customers will have to establish whether the architecture remains genuinely portable across mixed infrastructure or delivers its strongest protections only inside the Nvidia stack.
No security layer can guarantee that an autonomous agent behaves correctly. Policies can be misconfigured, legitimate credentials can be compromised, and the distinction between an authorised action and an undesirable one can be difficult to express technically when business processes contain exceptions and judgement calls.
Moving enforcement below the application nevertheless changes the failure model. Rather than relying entirely on the agent to respect instructions embedded in its own environment, companies can impose limits through infrastructure that remains outside the agent’s control.
As autonomous systems gain more persistent roles in software development, customer operations, infrastructure management, and physical systems, that separation is likely to become part of ordinary enterprise security architecture. The question shifts from whether an agent can complete a task to whether the surrounding systems can prove where it acted, what it accessed, and whether they can stop it when it crosses a boundary.












